Sector wise readiness
Manufacturing: low data volume does not mean no obligation
- Does DPDP apply to manufacturers?
- Yes. Selling only to businesses does not put you outside the Act. You have a workforce, so payroll, HR records and biometric attendance at the plant gate are personal data, and that alone puts the full baseline on you regardless of how little customer data you hold.
- Who this affects
- Manufacturers, industrial firms and B2B suppliers of any size, including those with no consumer customers at all.
- What to do about it
- For most manufacturers the honest answer is that you do not need to buy anything. Fix the HR and workforce side: know what employee data you hold, why you hold it, how long you keep it, and who can reach it. Biometric attendance deserves particular attention.
The most common reaction I get from manufacturers and B2B suppliers: "we barely hold any personal data, we sell to businesses, not people."
Mostly true, and it still does not get you out. The auditor's line for this sector is short: low personal data volume does not mean no obligation. Employee data alone triggers the full baseline.
You have a workforce. Payroll, HR records, biometric attendance at the plant gate. That is personal data, and it puts the whole baseline on you regardless of how B2B your sales are.
The good news is that this is one of the few sectors where the honest answer is that you probably do not need to buy anything. What you need is your HR systems in order and your vendors under contract.
A sector map is a superset, not a launch checklist.
What applies from the start, whatever your size
- ✅ Notice
- ✅ Consent or a lawful basis for every purpose
- ✅ Security safeguards
- ✅ Rights handling
- ✅ Grievance mechanism
- ✅ Processor contracts
- ✅ Breach response
The small number of things specific to this sector
- ✅ Workforce data is your main exposure. Employees, plus B2B contacts and warranty or customer registrations. Start there, not with a compliance product.
- ✅ Bind dealers and distributors. Dealers, distributors and service partners handling customer data all need a Data Processing Agreement. This chain is usually informal and undocumented.
- ✅ Warranty and registration retention. End customer registrations need a retention and erasure rule. A warranty database from 2014 is not a live purpose.
What almost certainly does not apply
- ❌ SDF obligations. Unlikely on personal data volume alone, and in any case Significant Data Fiduciary status comes only on Government notification.
- ❌ A mandatory Data Protection Officer, annual DPIAs and independent audits. These attach to SDF status once notified.
- ❌ A dedicated DPDP product. For most manufacturers, HRIS access control and vendor agreements carry the load.
The better question
The better question is not "do we hold enough personal data to matter?"
It is "have we treated our own employees' data as seriously as we treat our customers' contracts?"
Law creates obligations. Scale and risk influence implementation. But the baseline does not scale down with data volume. One employee is enough to trigger it.
If you run a manufacturing business, is your dealer network under contract for data, or just for sales?